DevMan is a ransomware operation that emerged in 2025 and is widely associated with the DragonForce ecosystem through code lineage, operational overlap, and affiliate relationships. Reporting variously characterizes it as a closed operation and as a ransomware-as-a-service program; the strongest consistent assessment is that DevMan operated affiliate-enabled ransomware infrastructure with builder functionality and victim-management workflows. The malware family has been observed in Windows-focused samples and later platform support claims for Linux and VMware ESXi, with versions reportedly evolving from earlier C++ implementations to later Rust-based builds.
DevMan is used for double-extortion operations against high-value organizations, including technology, healthcare, financial services, professional services, government, and industrial targets. Public victim reporting indicates substantial activity in 2025 and early 2026, with notable concentration in the United States as well as activity across Asia and Africa. The operation has also expressed interest in critical infrastructure, and reporting has described a separate SCADA-focused encryptor claimed by the operators, although details on real-world deployment of that component remain limited.
Observed and reported locker capabilities include privilege checks, impairment of security controls, termination of processes and services, inhibition of recovery mechanisms, event-log clearing, discovery of local and network shares, SMB-based propagation behavior, and lateral movement across victim environments. Encryption behavior has been tied to ChaCha20-Poly1305 in platform reporting, while analyzed samples linked to DevMan show DragonForce/Conti-derived design traits such as multiple encryption modes and use of Windows Restart Manager to access locked files. Some analyzed DevMan-branded builds appeared to be lightly customized DragonForce derivatives rather than wholly distinct codebases, reinforcing the assessment that DevMan either reused or closely inherited DragonForce tooling.
DevMan has been linked to affiliate relationships or prior operational ties involving Qilin, DragonForce, Apos, and RansomHub, and one operator has been identified in reporting as a former Conti and Black Basta affiliate. Multiple reports also note strong overlap between DevMan and the later Vect ransomware family, including shared builder strings, similar ransom-note structure, and matching conventions in lateral-movement task naming, suggesting possible operator continuity, rebranding, or shared tooling. Overall, DevMan is best understood as a financially motivated ransomware threat closely tied to the DragonForce lineage, with cross-platform ambitions, affiliate-oriented operations, and tradecraft focused on enterprise-wide disruption and extortion.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The operators of the DevMan ransomware-as-a-service (RaaS) scheme are maintaining a dedicated web platform that offers affiliates the ability to build payloads, oversee earnings, and manage various aspects related to victims.
Devman declined by 70%, from 82 victims to 25. The ransomware’s operator “Tramp”, a former Conti and Black Basta affiliate, was added to Interpol’s wanted list in January 2026.
“Security researchers have reportedly identified Devman ransomware payloads that are build on DragonForce infrastructure.”
11 distinct techniques documented for this family, organized by ATT&CK tactic.
An analysis of the Windows version has identified functions related to privilege checking to determine if it's running as an administrator, security-control impairment, process and service termination, recovery inhibition, event log clearing, local and network-share discovery, lateral movement, multi-threaded encryption, ransom-note creation, and optional self-deletion.
An analysis of the Windows version has identified functions related to privilege checking to determine if it's running as an administrator, security-control impairment, process and service termination, recovery inhibition, event log clearing, local and network-share discovery, lateral movement, multi-threaded encryption, ransom-note creation, and optional self-deletion.
An analysis of the Windows version has identified functions related to privilege checking to determine if it's running as an administrator, security-control impairment, process and service termination, recovery inhibition, event log clearing, local and network-share discovery, lateral movement, multi-threaded encryption, ransom-note creation, and optional self-deletion.
The latest version of the portal allows affiliates to create a locker for Windows, ESXi, or Linux. An analysis of the Windows version has identified functions related to privilege checking to determine if it's running as an administrator, security-control impairment, process and service termination, recovery inhibition, event log clearing, local and network-share discovery, lateral movement, multi-threaded encryption, ransom-note creation, and optional self-deletion.
An analysis of the Windows version has identified functions related to privilege checking to determine if it's running as an administrator, security-control impairment, process and service termination, recovery inhibition, event log clearing, local and network-share discovery, lateral movement, multi-threaded encryption, ransom-note creation, and optional self-deletion.
An analysis of the Windows version has identified functions related to privilege checking to determine if it's running as an administrator, security-control impairment, process and service termination, recovery inhibition, event log clearing, local and network-share discovery, lateral movement, multi-threaded encryption, ransom-note creation, and optional self-deletion.
An analysis of the Windows version has identified functions related to privilege checking to determine if it's running as an administrator, security-control impairment, process and service termination, recovery inhibition, event log clearing, local and network-share discovery, lateral movement, multi-threaded encryption, ransom-note creation, and optional self-deletion. | The operators of the DevMan ransomware-as-a-service (RaaS) scheme are maintaining a dedicated web platform that offers affiliates the ability to build payloads, oversee earnings, and manage various aspects related to victims.
An analysis of the Windows version has identified functions related to privilege checking to determine if it's running as an administrator, security-control impairment, process and service termination, recovery inhibition, event log clearing, local and network-share discovery, lateral movement, multi-threaded encryption, ransom-note creation, and optional self-deletion.
An analysis of the Windows version has identified functions related to privilege checking to determine if it's running as an administrator, security-control impairment, process and service termination, recovery inhibition, event log clearing, local and network-share discovery, lateral movement, multi-threaded encryption, ransom-note creation, and optional self-deletion.
An analysis of the Windows version has identified functions related to privilege checking to determine if it's running as an administrator, security-control impairment, process and service termination, recovery inhibition, event log clearing, local and network-share discovery, lateral movement, multi-threaded encryption, ransom-note creation, and optional self-deletion.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A ransomware-as-a-service operation with a dedicated affiliate portal for payload building, victim management, earnings, team coordination, and payout handling. Its Windows locker includes privilege checks, security-control impairment, process and service termination, recovery inhibition, event log clearing, local and network-share discovery, lateral movement, multi-threaded encryption, ransom-note creation, and optional self-deletion. It encrypts files using ChaCha20-Poly1305 and also offers Windows, ESXi, and Linux lockers, with a separate SCADA-focused encryptor mentioned for critical infrastructure attacks.
Devman is a ransomware family linked in reporting to Vect through shared builder strings, matching DM-prefixed lateral movement task naming, and similar ransom notes. The content suggests possible operator continuity, rebranding, or code overlap.
A ransomware family linked in reporting to Vect through shared strings, ransom-note similarities, and matching lateral movement task naming conventions. The content suggests possible operator continuity, rebranding, or code overlap.
A ransomware operation whose activity collapsed after pressure on its operator and shutdown of its leak sites; it had links to a former Conti and Black Basta affiliate.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.